CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2009-0393

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0394

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to execute arbitrary SQL commands via the school parameter.

    Published: 3 Feb 2009
    7.5
    High

    CVE-2009-0395

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 3 Feb 2009
    5.4
    Medium

    CVE-2009-0355

    Last Modified: 23 Apr 2026

    components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.

    Published: 3 Feb 2009
    2.6
    Low

    CVE-2009-0354

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.

    Published: 3 Feb 2009
    5.1
    Medium

    CVE-2009-0356

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs. NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.

    Published: 3 Feb 2009
    10
    Critical

    CVE-2009-0352

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.

    Published: 3 Feb 2009
    10
    Critical

    CVE-2009-0353

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.

    Published: 3 Feb 2009
    5
    Medium

    CVE-2009-0357

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

    Published: 3 Feb 2009
    3.3
    Low

    CVE-2009-0358

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.

    Published: 3 Feb 2009
    6.9
    Medium

    CVE-2008-4990

    Last Modified: 23 Apr 2026

    Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/enomalism2.pid temporary file.

    Published: 2 Feb 2009
    4.3
    Medium

    CVE-2009-0273

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allow remote attackers to inject arbitrary web script or HTML via the (1) User.id and (2) Library.queryText parameters to gw/webacc, and other vectors involving (3) HTML e-mail and (4) HTML attachments.

    Published: 2 Feb 2009
    7.2
    High

    CVE-2009-0390

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows local users to send signals to arbitrary processes by populating the /tmp/enomalism2.pid file with command-line arguments for the kill program.

    Published: 2 Feb 2009
    7.8
    High

    CVE-2009-0391

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows attackers to read arbitrary files via unknown vectors.

    Published: 2 Feb 2009
    6.8
    Medium

    CVE-2009-0272

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Novell GroupWise WebAccess 6.5x, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a, and 8.0 allows remote attackers to insert e-mail forwarding rules, and modify unspecified other configuration settings, as arbitrary users via unknown vectors.

    Published: 2 Feb 2009
    6.8
    Medium

    CVE-2008-6018

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2008-6020

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Views module 6.x before 6.x-2.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to "an exposed filter on CCK text fields."

    Published: 2 Feb 2009
    10
    Critical

    CVE-2008-6021

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Attachmate Reflection for Secure IT UNIX Client and Server before 7.0 SP1 have unknown impact and attack vectors, aka "security vulnerabilities found by 3rd party analysis."

    Published: 2 Feb 2009
    7.5
    High

    CVE-2008-6022

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the ugamela_root_path parameter.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2008-6017

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in messages.php in I-Rater Basic allows remote attackers to execute arbitrary SQL commands via the idp parameter.

    Published: 2 Feb 2009
    9.3
    Critical

    CVE-2009-0389

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2008-6023

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1, allows remote attackers to execute arbitrary PHP code via a URL in the xnova_root_path parameter.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2008-6019

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EACOMM DO-CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Feb 2009
    5.4
    Medium

    CVE-2008-6024

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFSv4 client module in the kernel on Sun Solaris 10 and OpenSolaris before snv_37, when automountd is used, allows user-assisted remote attackers to cause a denial of service (unresponsive NFS filesystems) via unknown vectors.

    Published: 2 Feb 2009
    4.3
    Medium

    CVE-2009-0382

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Internationalization (i18n) Translation 5.x before 5.x-2.5, a module for Drupal, allows remote attackers with "translate node" permissions to bypass intended access restrictions and read unpublished nodes via unspecified vectors.

    Published: 2 Feb 2009
    6.4
    Medium

    CVE-2009-0383

    Last Modified: 23 Apr 2026

    delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.

    Published: 2 Feb 2009
    6.8
    Medium

    CVE-2009-0384

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Feb 2009
    9.3
    Critical

    CVE-2009-0385

    Last Modified: 23 Apr 2026

    Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2009-0377

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mpid parameter in a sign action to index.php, a different vector than CVE-2008-3132.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2009-0381

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a products action to index.php.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2009-0380

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the bid parameter in a showbiz action to index.php, a different vector than CVE-2008-0607. NOTE: CVE disputes this issue, since neither "showbiz" nor "bid" appears in the source code for SOBI2

    Published: 2 Feb 2009
    4.3
    Medium

    CVE-2009-0378

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the pet parameter in a sign action.

    Published: 2 Feb 2009
    7.5
    High

    CVE-2009-0379

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a showgame action to index.php, a different vector than CVE-2008-0761.

    Published: 2 Feb 2009
    5
    Medium

    CVE-2009-0478

    Last Modified: 23 Apr 2026

    Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

    Published: 2 Feb 2009
    4.3
    Medium

    CVE-2009-0204

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HP Select Access 6.1 and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jan 2009
    4.3
    Medium

    CVE-2009-0369

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.

    Published: 30 Jan 2009
    7.2
    High

    CVE-2009-0370

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."

    Published: 30 Jan 2009
    7.5
    High

    CVE-2009-0373

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.

    Published: 30 Jan 2009
    6.8
    Medium

    CVE-2009-0371

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.

    Published: 30 Jan 2009
    6.5
    Medium

    CVE-2009-0372

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6006

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code via a URL in the minsoft_path parameter to (1) utdb_access.php and (2) utgn_message.php in utility/.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6007

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jan 2009
    4.3
    Medium

    CVE-2008-6012

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a viewEntry action.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6013

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Freeway before 1.4.3.210 allow remote attackers to execute arbitrary SQL commands via unspecified vectors involving the (1) advanced search result and (2) service resource pages.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6014

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in scripts/links.php in Rianxosencabos CMS 0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6009

    Last Modified: 23 Apr 2026

    SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.

    Published: 30 Jan 2009
    5
    Medium

    CVE-2008-6008

    Last Modified: 23 Apr 2026

    hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for hyBook.mdb.

    Published: 30 Jan 2009
    5
    Medium

    CVE-2008-6010

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6016

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jan 2009
    7.5
    High

    CVE-2008-6011

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 30 Jan 2009